The problems began in August 2022 when unknown attackers made off with technical data from LastPass’ servers. A few months later, the cybercriminals were back, using the stolen data to get their hands on user password vaults. LastPass sought to assuage fears by reminding everyone that the vaults are encrypted and LastPass does not store the master passwords that would unlock them. Although, the company’s security practices have since been roundly criticized by experts in the field, as well as its competitors.
The unidentified plaintiff claims their cryptocurrency was secured with a unique password generated by LastPass and used the service to store “highly sensitive private keys” for accessing the funds. And yet, the user’s crypto wallet was cleaned out shortly after the breach. If, as the Pennsylvania man claims, the keys were only stored in LastPass, that shows the vault files are not as secure as the company claims. Other stories are popping up on the internet that lend credence to the claims in the lawsuit. Users who move their password data to Google have seen their unique LastPass passwords reported as compromised, and others say they’ve seen more suspicious phishing attempts that may be related to the breach.
The lawsuit alleges that LastPass mischaracterized its security practices as “stronger-than-typical” when, in fact, it was lax. For example, it only started requiring new master passwords to be 12 characters long in 2018, and it runs only 100,100 iterations of the PBKDF2 algorithm to hash passwords when the industry standard is 310,000 iterations. The plaintiff also cites the company’s “unreasonably delayed” notification of users as an example of negligence.
You don’t have to do anything right now if you think you’re a member of the class. These cases can take years to resolve, but the upshot is you don’t have to pay any legal fees. You may end up with a small payout at the conclusion, but be wary of emails promising settlement money or you could end up hacked all over again.
Now read:
- UK Police Arrest Alleged GTA 6 Hacker
- Plex Media Servers Being Used to Amplify DDoS Attacks
- Minor Change in Chrome 80 Cripples Major Hacking Marketplace
No comments:
Post a Comment